Cup'n'String
Join Waitlist

© 2026 Cup'n'String

All Guides/Azure Network Security Groups Guide
AZ

Azure Network Security Groups

Integration & Setup Manual

Azure Network Security Groups Integration Guide

Overview

Cup’n’String Guard integrates with Azure Network Security Groups (NSGs) to enforce AI tool network policies for Azure-hosted developer environments and CI/CD infrastructure. Guard uses the Azure Resource Manager (ARM) API to declaratively apply NSG security rules with ETag-guarded, async operations — ensuring no concurrent modifications cause rule drift.

Support level

Cloud-Native Rules — ARM declarative apply with ETag-based concurrency control and async operation polling. Guard owns only its tagged rules in designated NSGs.

Observe to audit current NSG rules against the desired AI tool policy baseline, then Enforce to activate automatic rule reconciliation.

Known limitations

  • NSG rules apply at the subnet or NIC level — per-process enforcement is not available.
  • Guard manages NSGs in one resource group per provider instance; add multiple providers for multi-region or multi-group deployments.
  • ARM declarative apply sends the full NSG rule set on each change — concurrent external modifications may be overwritten.

Setup outline

  1. Confirm the supported platform and deployment requirements with your administrator.
  2. Use a dedicated integration identity with the minimum required permissions and validated TLS connections.
  3. Review policy in your environment before enabling enforcement, then verify the intended access outcomes.

Contact the Cup’n’String team for deployment-specific configuration and verification guidance. Never share credentials in support messages or screenshots.

Integration Info

Support LevelCloud-Native Rules
CategoryFirewalls
Setup ComplexityMedium
Governed Safeguards
Network

Links

Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.

Supported Environments Matrix